Latest Cybersecurity News and Articles
28 April 2025
IBM will invest more than $30 billion in research and development to advance and continue its American manufacturing of mainframe and quantum computers.
The post IBM’s $150 Billion US Investment to Boost Quantum Innovation and National Security appeared first on SecurityWeek.
28 April 2025
Palo Alto Networks is acquiring AI security company Protect AI in a deal previously estimated at $650-700 million.
The post Palo Alto Networks to Acquire AI Security Firm Protect AI appeared first on SecurityWeek.
28 April 2025
Zero-trust network security solutions provider NetFoundry has raised $12 million in funding from SYN Ventures.
The post NetFoundry Raises $12 Million for Network Security Solutions appeared first on SecurityWeek.
28 April 2025
This tension between hard-edged risk realism and breathless AI evangelism sets an unmistakable tone for a bellwether conference where 40,000-plus gather to do business.
The post JPMorgan Chase CISO Fires Warning Shot Ahead of RSA Conference appeared first on SecurityWeek.
28 April 2025
Outdated operating systems are run on approximately 50% of mobile devices.
28 April 2025
San Francisco identity security play Veza closes a Series D fund round led by New Enterprise Associates (NEA).
The post Veza Banks $108 Million Series D at $808 Million Valuation appeared first on SecurityWeek.
28 April 2025
Threat actors have exploited a zero-day vulnerability in Craft CMS to execute PHP code on hundreds of websites.
The post Craft CMS Zero-Day Exploited to Compromise Hundreds of Websites appeared first on SecurityWeek.
28 April 2025
VeriSource Services says the personal information of 4 million people was compromised in a February 2024 cyberattack.
The post 4 Million Affected by VeriSource Data Breach appeared first on SecurityWeek.
28 April 2025
What happens when cybercriminals no longer need deep skills to breach your defenses? Today’s attackers are armed with powerful tools that do the heavy lifting — from AI-powered phishing kits to large botnets ready to strike. And they’re not just after big corporations. Anyone can be a target when fake identities, hijacked infrastructure, and insider tricks are used to slip past security
28 April 2025
CISA warns of flaws in Siemens, Schneider Electric, and ABB hardware.
28 April 2025
Planet Technology industrial switches and network management products are affected by several critical vulnerabilities.
The post Critical Vulnerabilities Found in Planet Technology Industrial Networking Products appeared first on SecurityWeek.
28 April 2025
Not every security vulnerability is high risk on its own - but in the hands of an advanced attacker, even small weaknesses can escalate into major breaches. These five real vulnerabilities, uncovered by Intruder’s bug-hunting team, reveal how attackers turn overlooked flaws into serious security incidents.
1. Stealing AWS Credentials with a Redirect
Server-Side Request Forgery (SSRF) is a
28 April 2025
Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco.
The post RSA Conference 2025 – Pre-Event Announcements Summary (Part 3) appeared first on SecurityWeek.
28 April 2025
MTN Group says the personal information of certain customers was compromised in a cybersecurity incident.
The post African Telecom Giant MTN Group Discloses Data Breach appeared first on SecurityWeek.
28 April 2025
Government and telecommunications sectors in Southeast Asia have become the target of a "sophisticated" campaign undertaken by a new advanced persistent threat (APT) group called Earth Kurma since June 2024.
The attacks, per Trend Micro, have leveraged custom malware, rootkits, and cloud storage services for data exfiltration. The Philippines, Vietnam, Thailand, and Malaysia are among the
28 April 2025
Oregon’s environmental agency won’t say if a group of hackers stole data in a cyberattack that was first announced earlier this month.
The post Oregon Agency Won’t Say If Hackers Stole Data in Cyberattack appeared first on SecurityWeek.
28 April 2025
Cybersecurity researchers are warning about a large-scale phishing campaign targeting WooCommerce users with a fake security alert urging them to download a "critical patch" but deploy a backdoor instead.
WordPress security company Patchstack described the activity as sophisticated and a variant of another campaign observed in December 2023 that employed a fake CVE ploy to breach sites running
28 April 2025
Threat actors have been observed exploiting two newly disclosed critical security flaws in Craft CMS in zero-day attacks to breach servers and gain unauthorized access.
The attacks, first observed by Orange Cyberdefense SensePost on February 14, 2025, involve chaining the below vulnerabilities -
CVE-2024-58136 (CVSS score: 9.0) - An improper protection of alternate path flaw in the Yii PHP
28 April 2025
Explore industry moves and significant changes in the industry for the week of April 28, 2025. Stay updated with the latest industry trends and shifts.
28 April 2025
Internet crime losses exceeded $16 billion in 2024.